api-design-reviewer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and Python tools (api_linter.py, api_scorecard.py, breaking_change_detector.py) for evaluating API designs. The scripts use standard Python libraries to perform structural and semantic checks on JSON-based API specifications.
  • [INDIRECT_PROMPT_INJECTION]: The skill scripts ingest untrusted external data in the form of OpenAPI/Swagger JSON files.
  • Ingestion points: The scripts scripts/api_linter.py, scripts/api_scorecard.py, and scripts/breaking_change_detector.py accept file paths to API specifications as CLI arguments and load them using json.load().
  • Boundary markers: None present; the scripts parse the provided files directly.
  • Capability inventory: The scripts are restricted to file reading/writing (to user-provided output paths) and logic-based analysis. They do not utilize network libraries, eval, exec, or subprocess for dangerous operations.
  • Sanitization: The scripts use standard JSON parsing which ensures basic data integrity, followed by structural validation logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:32 PM